BlackHartBlackHart
D1

Access Control

Permission models, admin surface, reentrancy protection, and authorization boundaries. #1 exploit vector by dollar loss in DeFi history.

Weight 18%80% confidence
78
Good
info

How This Score Is Built

Permission models, admin surface, reentrancy protection, and authorization boundaries. #1 exploit vector by dollar loss in DeFi history.

+23Strong positive
+12Positive
+5Slight positive
−15Strong negative
−8Negative
−3Slight negative

Score Composition

-11

Guardian can set fees and pause without timelock -- ops flexibility vs risk tradeoff

Strong negativeopen_in_newSource CodeMay 4, 2026
-11

No granular per-collateral admin roles (single Guardian controls all)

Strong negativeopen_in_newSource CodeMay 4, 2026
0

ProxyAdmin owned by Governor timelock -- upgrade path gated

Neutralopen_in_newSource CodeMay 4, 2026
+39

Two-tier access: onlyGovernor (full power) + onlyGuardian (ops/fees)

+39

Minter role pattern on AgToken restricts supply inflation

Strong positiveopen_in_newSource CodeMay 4, 2026

Evidence Chain (2 files)

GitHub APIMay 17, 2026, 06:58 PM
open_in_newGitHub (/)
sha256:5f6764238b92...
BlackHart AnalysisMay 4, 2026, 09:00 PM
open_in_newAccess Control — Source Code
sha256:ff51777c4839...

Score History

Automated pipeline dimension update